Deployment facts
The page lists ChimeEdu’s primary domain, ports, TLS posture, and a note about institutional networks: all traffic is over HTTPS on port 443, including the live-quiz connection, and there is no IPv6 address to allow.The copy-paste allowlist
Copy N hosts puts the complete hostname allowlist on your clipboard, ready for a firewall or filtering console. Below it, the Third-party origins table explains what each host is for and when it’s needed — maps, sharing, Google Drive, billing, media embeds, search, real-time quizzes — so your team can allow only what your school uses. Rows marked optional (analytics) can be blocked without affecting the platform. Fonts and other assets are served from ChimeEdu’s own domain, so no font or CDN hosts need to be allowed.Rate limits and school networks
Many devices behind one school internet connection look like one address to ChimeEdu. Its rate limits are sized for that — a whole campus behind one address is expected and supported.Single sign-on (not active yet)
The Single Sign-On section lets you pre-stage configuration for Microsoft Entra / Azure AD, Google Workspace, Okta, or another provider: the email domains that would route to it, the sign-on or metadata URL, entity and tenant IDs, and notes. Configurations can be marked Draft or Ready.SSO is configuration-only for now. Nothing here changes how anyone signs in, and no secrets are stored. Staff and teachers continue to sign in with their ChimeEdu credentials until SSO launches.
.png?fit=max&auto=format&n=laKFmI15-RqGTiKZ&q=85&s=c256af0c511b71a786811c4ddd6e2798)
.png?fit=max&auto=format&n=laKFmI15-RqGTiKZ&q=85&s=a8410b0dd9a9f02bd5f7ad7bfac2649e)